In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
History

Mon, 06 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Progress
Progress whatsup Gold
CPEs cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Progress
Progress whatsup Gold

Tue, 31 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 31 Dec 2024 10:45:00 +0000

Type Values Removed Values Added
Description In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
Title WhatsUp Gold - Public API signing key rotation issue
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published: 2024-12-31T10:31:56.107Z

Updated: 2025-01-04T04:55:29.674Z

Reserved: 2024-12-03T19:30:25.687Z

Link: CVE-2024-12108

cve-icon Vulnrichment

Updated: 2024-12-31T15:34:20.314Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-31T11:15:06.780

Modified: 2025-01-06T16:51:11.320

Link: CVE-2024-12108

cve-icon Redhat

No data.